Datenexfiltration
Data Exfiltration
Datenexfiltration
Data exfiltration is the unauthorised outflow of data from an organisation to the outside — the actual objective of many attacks. It is often the last step in a longer chain and frequently takes place disguised, so as not to stand out. Where it succeeds, the greatest damage and the greatest legal consequences arise.
History & facts. Attackers often disguise the outflow as legitimate traffic — via common web protocols, encrypted connections, cloud storage or even hidden in inconspicuous carriers (steganography). In double extortion, stolen data is used additionally to encryption as leverage. Because the outflow runs over the network, it leaves traces there: unusual data volumes, atypical destinations or connections to unknown counterparts.
Outlook & recommendation. Detection starts with behaviour: what leaves the network, where to and in what volume? Network observation (Network Detection and Response (NDR)/NSM) and matching against known indicators (Command and Control (C2) destinations) can reveal an ongoing outflow before it is completed. Preventive effects come from data minimisation, segmentation and the control of outbound connections. Since an outflow of personal data simultaneously triggers the GDPR notification duty, fast detection is also legally decisive.